Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7qmg-grcp-qf25 | GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geoserver
Geoserver geoserver |
|
| Vendors & Products |
Geoserver
Geoserver geoserver |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to the target file, the target file can not already exist and all parent directories must already exist. Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations where the web interface is either disabled or completely removed are not affected since the vulnerability exists in one of the web pages. | |
| Title | GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-24T03:56:00.821Z
Reserved: 2025-06-17T02:28:39.716Z
Link: CVE-2025-52465
Updated: 2026-06-18T15:24:28.449Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:01Z
Github GHSA